An improved lightweight anonymous user authenticated session key exchange scheme for Internet of Things

被引:9
|
作者
Kumar, Devender [1 ]
Jain, Siddharth [2 ]
Khan, Aasif [2 ]
Pathak, Pranav Sarv [2 ]
机构
[1] NSUT, Dept Informat Technol, New Delhi, India
[2] NSIT, Div Informat Technol, New Delhi, India
关键词
Internet of Things; User authentication; Session key agreement; Security; Smart card loss attack; Stolen verifier attack; AGREEMENT SCHEME; MUTUAL AUTHENTICATION; PROVABLY SECURE; 3-FACTOR AUTHENTICATION; ACCESS-CONTROL; PROTOCOL; PRIVACY; DEVICES;
D O I
10.1007/s12652-020-02532-8
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Due to the myriad applications of the Internet of Things (IoT) in various sectors like healthcare, military, industry, safety, etc., there is also a need to secure these systems efficiently. The devices in such networks need to provide services to users in a secure manner. User authentication is a mechanism through which we can provide secure communication between IoT devices. Recently Banerjee et al. outlined a lightweight anonymous user authenticated session key exchange scheme for Internet of Things deployment, which uses three-factor authentication of a user such as smart card, password and biometric. In this paper, we cryptanalyze their scheme and find that it is not secure against smart card loss attack and stolen verifier attack. Then we have proposed an improved scheme to overcome the weaknesses of their scheme. We present the formal security analysis of our scheme using the random oracle model and informal security analysis to show that our scheme is secure against many known attacks. Its formal security verification is carried out using ProVerif tool. Its performance analysis is carried out with the related schemes which shows that our scheme is more secure than other schemes. Also, our scheme does not contain any storage table at the gateway side for authentication.
引用
收藏
页码:5067 / 5083
页数:17
相关论文
共 50 条
  • [1] An improved lightweight anonymous user authenticated session key exchange scheme for Internet of Things
    Devender Kumar
    Siddharth Jain
    Aasif Khan
    Pranav Sarv Pathak
    [J]. Journal of Ambient Intelligence and Humanized Computing, 2023, 14 : 5067 - 5083
  • [2] A Provably Secure and Lightweight Anonymous User Authenticated Session Key Exchange Scheme for Internet of Things Deployment
    Banerjee, Soumya
    Odelu, Vanga
    Das, Ashok Kumar
    Srinivas, Jangirala
    Kumar, Neeraj
    Chattopadhyay, Samiran
    Choo, Kim-Kwang Raymond
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2019, 6 (05) : 8739 - 8752
  • [3] An Improved Lightweight User Authentication Scheme for the Internet of Medical Things
    Kim, Keunok
    Ryu, Jihyeon
    Lee, Youngsook
    Won, Dongho
    [J]. SENSORS, 2023, 23 (03)
  • [4] Anonymous Lightweight Chaotic Map-Based Authenticated Key Agreement Protocol for Industrial Internet of Things
    Srinivas, Jangirala
    Das, Ashok Kumar
    Wazid, Mohammad
    Kumar, Neeraj
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2020, 17 (06) : 1133 - 1146
  • [5] Designing Anonymous Signature-Based Authenticated Key Exchange Scheme for Internet of Things-Enabled Smart Grid Systems
    Srinivas, Jangirala
    Das, Ashok Kumar
    Li, Xiong
    Khan, Muhammad Khurram
    Jo, Minho
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2021, 17 (07) : 4425 - 4436
  • [6] A Lightweight Key Generation Scheme for the Internet of Things
    Guo, Dengke
    Cao, Kuo
    Xiong, Jun
    Ma, Dongtang
    Zhao, Haitao
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (15) : 12137 - 12149
  • [7] Lightweight and escrow-less authenticated key agreement for the internet of things
    A. Simplicio, Marcos, Jr.
    Silva, Marcos V. M.
    Alves, Renan C. A.
    Shibata, Tiago K. C.
    [J]. COMPUTER COMMUNICATIONS, 2017, 98 : 43 - 51
  • [8] Lightweight collaborative key establishment scheme for the Internet of Things
    Ben Saied, Yosra
    Olivereau, Alexis
    Zeghlache, Djamal
    Laurent, Maryline
    [J]. COMPUTER NETWORKS, 2014, 64 : 273 - 295
  • [9] A lightweight Mutually Authenticated Key-Agreement scheme for Wireless Body Area Networks in Internet of Things Environment
    Gupta, Ankur
    Tripathi, Meenakshi
    [J]. MOBICOM'18: PROCEEDINGS OF THE 24TH ANNUAL INTERNATIONAL CONFERENCE ON MOBILE COMPUTING AND NETWORKING, 2018, : 804 - 806
  • [10] A three -factor anonymous user authentication scheme for Internet of Things environments
    Lee, Hakjun
    Kang, Dongwoo
    Ryu, Jihyeon
    Won, Dongho
    Kim, Hyoungshick
    Lee, Youngsook
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2020, 52